Attackers Abuse Google Apps Script to Deploy Phishing Websites
ID: 0b818edb-bf39-532b-8df9-453712724b3c
STIX ID: report--0b818edb-bf39-532b-8df9-453712724b3c
Feed Name: Cyber Press
Threat Score
This report describes a phishing campaign that leverages Google Apps Script-hosted pages to present fake invoice previews, harvest user credentials via a malicious PHP payload, and then redirect victims to legitimate Microsoft login pages to avoid detection. Provided IOCs include a script.google.com infection URL and several IP addresses, plus an attacker-controlled payload URL and IP; recommended mitigations emphasize employee training and robust email security solutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
